Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.
What if they threaten to release the data? Is it really preferable to let personal info flood the net rather than pay?
UCSF admits it paid NetWalker more than $1M ransom
51–60 of 68 posts
Re: UCSF admits it paid NetWalker more than $1M ransom
#52I'm imagining a scenario where a UCSF insider could coordinate this with someone by deliberately getting their system infected and then splitting the money with whoever is behind that NetWalker instance. Do you guys think that would work?
Re: UCSF admits it paid NetWalker more than $1M ransom
#53Earlier quoted context omitted.
That poses at most a minor roadblock. You just take over the backup-and-restore service for a little while and corrupt the backups as they get made. If anybody tries to verify the backups they just restore them correctly until they make their demand. Would probably add between $10K and $100K to the cost of attack (probably closer to $10K), so would probably be immaterial to the profitability of this attack. Therefore…
Ehh, a decent backup service ( https://www.tarsnap.com/ ) will give you the ability to make write-only backups over time, i.e. you should be able to roll back to 6 months ago without any chance of something corrupting the backup process. Of course, it depends how much data you're backing up.
Re: UCSF admits it paid NetWalker more than $1M ransom
#54The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?
I know the university I attended has learned nothing at all. State university in a wealthy US area with over 30,000 students. They still think security is forcing everyone to change passwords once every 6 months. No offer of 2fa of any sort for any service. I stopped using my email address between transcript requests because the whole student/faculty directory is rampant with student employees of local businesses sen…
Re: UCSF admits it paid NetWalker more than $1M ransom
#55Earlier quoted context omitted.
Why would you use crappy free Wordpress when you can pay a couple hundred thousand for a vastly superior MS SharePoint setup...
Or Drupal, if that's still a thing...
Re: UCSF admits it paid NetWalker more than $1M ransom
#56Earlier quoted context omitted.
I know the university I attended has learned nothing at all. State university in a wealthy US area with over 30,000 students. They still think security is forcing everyone to change passwords once every 6 months. No offer of 2fa of any sort for any service. I stopped using my email address between transcript requests because the whole student/faculty directory is rampant with student employees of local businesses sen…
Wouldn't happen to be UMD would it? I still remember when they had everything leaked in plain text...
Re: UCSF admits it paid NetWalker more than $1M ransom
#57Why isn't paying ransom illegal? Points: * Anytime any ransom is paid it is in the most literal sense funding ransom, even more directly than funding terror in the most direct way possible: when you send a check to ISIS that may or may not actually fund terror. Maybe whoever you sent it to is just good at making an ISIS recruitment page and doesn't do much real terror, just marketing. * But paying a ransom by definit…
Have I misunderstood your tone here, or do you actually believe this? Because bribery is illegal, and happens all of the time. The few who get caught get in trouble. Heck, Goldman Sachs does it when it's needed to land deals! [0]
I imagine the same would happen if ransom for ransomware was made illegal. Thieves would wouldn't care, what they do is already illegal. If someone they infect with ransomware can't figure out how to get them their money, what do they care? I'm sure their profits would go down, but it wouldn't stop. If anything it might just drive them to hit many smaller targets to get through volume what they can no longer get through big hits.
Re: UCSF admits it paid NetWalker more than $1M ransom
#58The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?
Re: UCSF admits it paid NetWalker more than $1M ransom
#59I think past generations are excused for not preparing this, simply because it was theoretical. It is real now. So designing systems that assume some part will be captured eventually, and then work to minimize that before they are even deployed, would be timely now.